file

Classification: Malicious

file is a malicious file sample. Linked to Turla, Oilrig activity. Reported by 2 threat sources, last seen 2023-03-18. Detected by 76 antivirus engines.

Detection summary

  • 76 antivirus detections (72% detection ratio)
  • 0 IDS alerts
  • 1 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: TURLA (G0010) OILRIG (G0049)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-03-18 17:00:03 2023-03-18 17:00:03
Turla Maltiverse 2023-03-03 04:26:37 2023-03-04 19:42:05 malicious-activity G0010 Turla
OilRig Maltiverse 2023-03-03 04:26:38 2023-03-04 19:41:50 malicious-activity G0049 OilRig

Tags

apt hacktool metasploit meterpreter apt34

Sample information

Filenames
file
File type
PE32 executable (console) Intel 80386 Mono/.Net as ...
Size
18944 bytes
MD5
6e4b7f13178ebc04304ee2b5ee646d09
SHA-1
663a78cb5e6f3ab54cd0d3f67bd8c9545b341d6f
SHA-256
24fe571f3066045497b1d8316040734c81c71dcb1747f1d7026cda810085fad7
First indexed
2023-03-04 19:41:50
Last updated
2025-11-24 02:33:22

Antivirus detections

EngineDetection
LionicTrojan.MSIL.Agent.4!c
DrWebTrojan.MulDrop9.16076
MicroWorld-eScanTrojan.Autoruns.GenericKD.41655882
FireEyeTrojan.Autoruns.GenericKD.41655882
ALYacTrojan.MSIL.Agent
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1109058
SangforTrojan.MSIL.Onoynah.mt
K7AntiVirusTrojan ( 00551ac81 )
AlibabaTrojan:MSIL/Turla.984123c1
K7GWTrojan ( 00551ac81 )
Cybereasonmalicious.3178eb
BitDefenderThetaGen:NN.ZemsilF.34266.bm0@ayBsFFc
SymantecBackdoor.Trojan
ESET-NOD32a variant of MSIL/Turla.I
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.Autoruns.GenericKD.41655882
NANO-AntivirusTrojan.Win32.Drop.frxjtr
AvastWin32:Trojan-gen
TencentMsil.Trojan.Agent.Wqnj
Ad-AwareTrojan.Autoruns.GenericKD.41655882
EmsisoftTrojan.Autoruns.GenericKD.41655882 (B)
ComodoMalware@#258ohdapn0w5s
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DG821
McAfee-GW-EditionBackDoor.gen.b
SophosMal/Generic-S
GDataTrojan.Autoruns.GenericKD.41655882
AviraTR/Agent.jcdsz
MAXmalware (ai score=100)
Antiy-AVLTrojan/MSIL.Agent
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Autoruns.Generic.D27B9E4A
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:MSIL/Onoynah
AhnLab-V3Trojan/Win32.Agent.C3331654
McAfeeBackDoor.gen.b
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.4173385363
TrendMicro-HouseCallTROJ_GEN.R002C0DG821
YandexTrojan.Agent!sPwyjrnKxGs
IkarusAPT34.Turla.Exange.Bot
FortinetMSIL/Agent.O!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
Antiy-AVLTrojan[APT]/MSIL.Turla
ArcabitIL:Trojan.MSILZilla.D7897
BitDefenderIL:Trojan.MSILZilla.30871
BkavW32.AIDetectMalware.CS
CAT-QuickHealTrojan.Ghanarava.1710488771646d09
CTXexe.trojan.msilzilla
DeepInstinctMALICIOUS
Elasticmalicious (moderate confidence)
EmsisoftIL:Trojan.MSILZilla.30871 (B)
F-SecureTrojan.TR/Agent.jcdsz
FireEyeGeneric.mg.6e4b7f13178ebc04
GDataIL:Trojan.MSILZilla.30871
GoogleDetected
Kingsoftmalware.kb.c.991
LionicTrojan.Win32.Turla.4!c
MalwarebytesGeneric.Malware/Suspicious
MaxSecureTrojan.Malware.8703358.susgen
MicroWorld-eScanIL:Trojan.MSILZilla.30871
RisingTrojan.Agent!8.B1E (CLOUD)
SangforBackdoor.Win32.Turla.ulxpg
SkyhighBackDoor.gen.b
SymantecBackdoor.Whisperer
TencentMsil.Trojan.Agent.Gtgl
VIPREIL:Trojan.MSILZilla.30871
VaristW32/ABTrojan.AZSC-8602
XcitiumMalware@#258ohdapn0w5s
alibabacloudTrojan:MSIL/Turla.I

Process list

NameCommand line
file.exe